voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-44942

📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: simplechat
🏢 Vendor: Microsoft
📅 Updated: 2026-07-16

📝 SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-44940

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: prompty
    🏢 Vendor: Microsoft
    📅 Updated: 2026-07-16

    📝 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-44939

      📊 Score: 8.7/10 (CVSS v3.1)
      📦 Product: prompty
      🏢 Vendor: Microsoft
      📅 Updated: 2026-07-16

      📝 Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core/src/core/loader.ts used gray-matter without overriding executable js and javascript...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-44936

        📊 Score: 9.3/10 (CVSS v3.1)
        📦 Product: kiota
        🏢 Vendor: Microsoft
        📅 Updated: 2026-07-16

        📝 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-44934

          📊 Score: n/a
          📦 Product: sglang
          🏢 Vendor: SGLang
          📅 Updated: 2026-07-16

          📝 SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remot...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-44933

            📊 Score: 9.3/10 (CVSS v3.1)
            📦 Product: kiota
            🏢 Vendor: Microsoft
            📅 Updated: 2026-07-16

            📝 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-suppl...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]AIWAF Project » 🌐
              @aiwafproject@mastodon.social

              Security configuration shouldn't have to be rewritten every time an application changes. AIWAF analyzes application source code to automatically identify routes, authentication, forms, APIs, and payloads, providing the context needed for smarter application security.

                [?]Kyle Reddoch (CybersecKyle) » 🌐
                @cyberseckyle@infosec.exchange

                [?]hackers-arise.official » 🌐
                @hackers_arise@mastodon.social

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Rare LG Ultragear deal slashes 33% off this 45-inch curved OLED gaming monitor

                LG's 45-inch UltraGear OLED drops to $1,349.99 at Amazon, a rare 33% off deal on this 5K2K ultrawide gaming monitor.

                androidauthority.com/lg-45-inc

                [Android Authority]

                  [?]Daniel Marsh » 🤖 🌐
                  @danielmarsh@social.thepixelspulse.com

                  CISA has mandated federal agencies patch a critical Oracle E-Business Suite flaw (CVE-2026-46817) by Saturday. This unauthenticated remote code execution vulnerability, affecting Oracle Payments, is already being actively exploited. The directive highlights a recurring problem: complex, legacy enterprise systems like EBS often remain unpatched for months, even years, until active exploitation forces…

                  tpp.blog/4ejiw93

                  🤖 This post was AI-generated.

                    [?]Hackread.com » 🌐
                    @Hackread@mstdn.social

                    📣🚨 A new and active malware campaign is abusing the ClickFix tactic and fake GitHub repos to trick users into installing fake browser extensions that steal personal and crypto wallet data.

                    Listen to or read this news: hackread.com/okobot-malware-cl

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Your favorite Tile trackers are picking up a Disney-themed glow-up

                      Life360 is giving its Tile trackers a visual refresh courtesy of its Disney collaboration.

                      androidauthority.com/disney-ti

                      [Android Authority]

                        [?]urlDNA.io :verified: » 🤖 🌐
                        @urldna@infosec.exchange

                        Possible Phishing 🎣
                        on: ⚠️hxxps[:]//tanvi-gupta-cmd[.]github[.]io/internspark-project/
                        🧬 Analysis at: urldna.io/scan/6a58b9c43b77500

                          [?]Bob Carver » 🌐
                          @cybersecboardrm@infosec.exchange

                          What are 'context bombs'? Get familiar with the new cybersecurity tool. | Mashable mashable.com/tech/context-bomb

                            [?]Daily CyberSecurity » 🌐
                            @DailyCyberSecurity@infosec.exchange

                            South Korean police uncovered a massive GitHub token leak exposing over 500 accounts. Discover the global impact and crucial security recommendations.

                            meterpreter.org/github-token-l

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              OnePlus officially gives up on the US and Europe

                              The OnePlus 15 was the company’s final US flagship. | Photo: Allison Johnson / The Verge OnePlus has confirmed what industry observers have long expected: it's quitting the US and European markets, and will no longer la…

                              theverge.com/tech/966404/onepl

                              [The Verge]

                                [?]Daily CyberSecurity » 🌐
                                @DailyCyberSecurity@infosec.exchange

                                SonicWall SMA1000 vulnerability CVE-2026-15409 (CVSS 10.0) is exploited in the wild. Public PoC enables remote code execution patch now.

                                securityonline.info/sonicwall-

                                  [?]Endoacustica » 🌐
                                  @cellularispia@mastodon.social

                                  📱 Most conversations now happen through messaging apps.

                                  Have you ever wondered how monitoring smartphones manage chats, notifications, cloud backups, and social media?

                                  ✨ In this article you'll discover:
                                  📩 How message monitoring works
                                  🔔 The role of push notifications
                                  ☁️ Cloud synchronization
                                  💬 WhatsApp, Telegram, Messenger & Instagram
                                  📱 Remote communication management
                                  🌐 Social media monitoring

                                  endoacustica.com/blogen/2026/0

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    COMPUTER COPS: Inside the big business of selling AI to the police

                                    I stood before a hulking glass and brick structure in the heart of Fort Worth, Texas. Thousands gathered inside to see what had been billed as "the future of policing in the digital age." As press, I was prohibited from…

                                    theverge.com/ai-artificial-int

                                    [The Verge]

                                      [?]urlDNA.io :verified: » 🤖 🌐
                                      @urldna@infosec.exchange

                                      Possible Phishing 🎣
                                      on: ⚠️hxxps[:]//gmxdhfdkjf[.]weebly[.]com
                                      🧬 Analysis at: urldna.io/scan/6a5897663b77500

                                        [?]The New Oil » 🤖 🌐
                                        @thenewoil@mastodon.thenewoil.org

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-44908

                                        📊 Score: 8.2/10 (CVSS v3.1)
                                        📦 Product: DFXServer
                                        🏢 Vendor: HCL Software
                                        📅 Updated: 2026-07-16

                                        📝 HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-44907

                                          📊 Score: 8.2/10 (CVSS v3.1)
                                          📦 Product: DFXServer
                                          🏢 Vendor: HCL Software
                                          📅 Updated: 2026-07-16

                                          📝 HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing the...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-44906

                                            📊 Score: 6.3/10 (CVSS v3.1)
                                            📦 Product: DFXServer
                                            🏢 Vendor: HCL Software
                                            📅 Updated: 2026-07-16

                                            📝 HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact ...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-44905

                                              📊 Score: 6.3/10 (CVSS v3.1)
                                              📦 Product: DFXServer
                                              🏢 Vendor: HCLSoftware
                                              📅 Updated: 2026-07-16

                                              📝 HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]FIRST.org » 🌐
                                                @firstdotorg@infosec.exchange

                                                New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
                                                Most teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

                                                Two independent data sets, isolated from one another, revealed strikingly similar problems:

                                                📄 IRPs too dense for anyone to actually use in a crisis
                                                ⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
                                                📊 Severity triage that doesn't reflect real business impact
                                                🧭 Unclear decision authority when it matters most
                                                👤 Key personnel unavailable, with no backup empowered to act
                                                🗣️ Discussions that never resolve into an actual decision
                                                ✅ Actions assigned but never tracked
                                                📢 Communication breakdowns, especially with non-technical stakeholders

                                                Read more: go.first.org/nqUbz

                                                  [?]Daily CyberSecurity » 🌐
                                                  @DailyCyberSecurity@infosec.exchange

                                                  Apache IoTDB fixes five flaws in its time-series database, including privilege escalation and an unauthenticated DoS. Upgrade to 2.0.10 now.

                                                  securityonline.info/apache-iot

                                                    [?]Hugo | DevOps | Cybersecurity » 🌐
                                                    @hugovalters@mastodon.social

                                                    Adobe: 1,915 CVEs, 10 CISA KEV exploited in wild. 94% unpatched. Trust Score: C. Attackers love your PDFs. Update Acrobat now.

                                                    valtersit.com/vendors/adobe/

                                                      [?]Daily CyberSecurity » 🌐
                                                      @DailyCyberSecurity@infosec.exchange

                                                      Discover how autonomous AI cyber attacks orchestrate entire hacks. Read the latest Check Point research detailing this dangerous shift in network security.

                                                      meterpreter.org/autonomous-ai-

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        Rival AI assistants could soon gain full access to Android features

                                                        The EU has mandated Google to open up Android to competing AI assistants.

                                                        androidauthority.com/eu-androi

                                                        [Android Authority]

                                                          [?]TierraSapiens » 🤖 🌐
                                                          @tierrasapiens@mastodon.social

                                                          🖲️
                                                          ⚫ Identity Attacks Overtake Exploits as Top Ransomware Cause
                                                          🔗 darkreading.com/identity-acces

                                                          Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent

                                                            [?]TierraSapiens » 🤖 🌐
                                                            @tierrasapiens@mastodon.social

                                                            🖲️
                                                            ⚫ Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
                                                            🔗 darkreading.com/application-se

                                                            Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.

                                                              [?]Daily CyberSecurity » 🌐
                                                              @DailyCyberSecurity@infosec.exchange

                                                              Discover how VeriChat AI revolutionizes hardware backdoor detection by analyzing microchip designs and uncovering hidden silicon threats.

                                                              meterpreter.org/hardware-backd

                                                                [?]N_{Dario Fadda} » 🌐
                                                                @nuke@poliversity.it

                                                                ☕ CYBERBRIEFING — Giovedì 16 luglio 2026

                                                                👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
                                                                ilpuntocyber.rfeed.it/article.


                                                                @informatica

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  Bixby just stopped talking to some Galaxy phone users, and Samsung can’t say why

                                                                  Bixby is choosing to work silently, and no one knows why.

                                                                  androidauthority.com/bixby-voi

                                                                  [Android Authority]

                                                                    [?]knoppix » 🌐
                                                                    @knoppix95@mastodon.social

                                                                    Researcher Candice Odgers argues evidence does not support social media as the main driver of rising youth mental health problems or blanket platform bans. 📱
                                                                    She advocates stronger platform accountability and targeted protections, while warning bans may push teens toward less transparent online spaces. 🔍

                                                                    🔗 theguardian.com/society/2026/j

                                                                      [?]knoppix » 🌐
                                                                      @knoppix95@mastodon.social

                                                                      The US House passed the KIDS Act, a bill that would introduce internet age-gating measures aimed at protecting minors online. 🏛️
                                                                      EFF argues the proposal would expand online surveillance instead of privacy protections, with broader implications for anonymity and the open web. 🔒

                                                                      @eff

                                                                      🔗 eff.org/deeplinks/2026/07/dont

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        Intel's EMIB packaging gains traction as chip designers look to skirt TSMC's CoWoS constraints — Google's reported decision for 9th-gen TPUs highlights Intel's att…

                                                                        Google has reportedly chosen Intel's EMIB-T over TSMC's CoWoS-L for its next-generation TPU, codenamed Humufish. But will Google be alone in its alleged decision?

                                                                        tomshardware.com/tech-industry

                                                                        [Tom's Hardware]

                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                          @urldna@infosec.exchange

                                                                          Possible Phishing 🎣
                                                                          on: ⚠️hxxps[:]//swipstore[.]cc
                                                                          🧬 Analysis at: urldna.io/scan/6a585f1d3b77500

                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                            @techwire@social.gamefan.net

                                                                            T-Mobile vs Verizon vs AT&T: New report reveals which carrier offers the best 5G experience

                                                                            All three carriers improved by leaps and bounds, but Verizon still leads the pack.

                                                                            androidauthority.com/t-mobile-

                                                                            [Android Authority]

                                                                              [?]Nicola Fabiano » 🌐
                                                                              @nicfab@fosstodon.org

                                                                              Daily Digest | 16 July 2026

                                                                              Your daily dose of Privacy, Data Protection, AI & Cybersecurity news.

                                                                              5 stories you should not miss.

                                                                              Read more: nicfab.eu/daily-digest/

                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                @techwire@social.gamefan.net

                                                                                Grab a DJI Osmo camera at some of lowest US prices ever

                                                                                An exclusive sale on AliExpress slashes prices on DJI’s Osmo ultra-compact handheld cameras, bringing them to some of the lowest prices in the U.S.

                                                                                tomshardware.com/pc-components

                                                                                [Tom's Hardware]

                                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                                  @urldna@infosec.exchange

                                                                                  Possible Phishing 🎣
                                                                                  on: ⚠️hxxps[:]//small-colleagues-736102[.]framer[.]app
                                                                                  🧬 Analysis at: urldna.io/scan/6a5897583b77500

                                                                                    [?]BeeSINT » 🌐
                                                                                    @BeeSINT@mastodon.social

                                                                                    🎣 Phishing Spotlight

                                                                                    v0-coinbase-login-page[.]vercel[.]app

                                                                                    🔒 SSL: exp. 2026-09-26
                                                                                    🌐 Stack: Vercel

                                                                                    🔗 beesint.com/pulse/24216de9-cc1

                                                                                      Back to top - More...